KIKOMAN · LEGAL
Privacy Policy
This document answers three questions: what we collect about you, what we do with it, and how you delete it. No "including but not limited to … and other information" — where a list can be complete, we made it complete.
The short version
- To register we need one phone number or one email address — your choice. No name, no ID number, no address, no payment details.
- There is no password, only a one-time code.
- We record a device fingerprint and your IP address for exactly one purpose: identifying devices to prevent abuse of the free allowance.
- The servers are in Hong Kong, China. Under Chinese law that is a cross-border transfer of personal information, which is why sign-in asks for a separate tick for it.
- To delete your account: tap "Delete account" in the app. Your phone number / email is unbound and removed immediately and can be registered again straight away.
Who processes your information
Your personal information is processed by the person below. The law requires us to state this clearly, including a real name and a contact that actually reaches someone:
- Personal information handler
- 罗智予(个人)
- Legal nature
- Individual developer, not a company. There is no corporate entity and no business licence behind this service
- Phone
- 17725094982
- Contact email
- l2539527429@gmail.com
- Service covered
- Cargo Load Simulator (imkikoman.com and imkikoman.com/app)
- Effective date of this version
- 2026-08-08 (version 2026-08-08)
"We" below means that person. The service is currently run by one individual; no other staff can reach your data.
What we collect, why, for how long, and where it lives
This table is the heart of the policy. If it isn't in the table, we don't collect it.
| What | Why | How long | Where |
|---|---|---|---|
| Phone number or email address one of the two at sign-up; you may bind both to one account | To create and identify your account, send sign-in codes, and contact you about the service if needed | While the account exists. Deleted from the database immediately on account deletion; the number/address can then be registered again | Server in Hong Kong, China |
| Email one-time code stored only as a salted hash | To confirm the sign-in is really you | 5 minutes; cleared once used or expired | Server in Hong Kong, China |
| SMS one-time code | To confirm the sign-in is really you | We never store it — the SMS provider generates and verifies it; it is not in our database at all | At the SMS provider (see section 06) |
| Session credential only a hash is stored in the database | To keep you signed in without a new code every time | 30 days; invalidated immediately on sign-out or account deletion | Server in Hong Kong, China + a cookie in your browser |
| Device fingerprint first 32 hex characters of a sha256 | Identifying devices to prevent abuse of the free allowance. Nothing else — no profiling, no advertising | The server-side run counter is kept long-term (the free allowance is a lifetime one); the local cache in your browser is recomputed after 30 days | Server in Hong Kong, China + your browser |
| IP address | Per-IP caps on the free allowance, rate limiting, and detecting abuse and attacks | Kept alongside the corresponding run records and consent records | Server in Hong Kong, China |
| Usage records timestamp, how many items this run had, which account or anonymous identifier it belongs to | Free-allowance accounting, troubleshooting, capacity planning | Long-term (see the note below the table) | Server in Hong Kong, China |
| Consent records time of consent, the IP at the time, a hash of the browser identifier, and the policy version you agreed to | To evidence that consent was obtained and which version it covered — the law requires us to be able to show this | Long-term; after account deletion no longer linked to your phone number or email | Server in Hong Kong, China |
The two "long-term" entries are the free-allowance counters and the consent evidence. The free allowance is 7 runs for life; deleting the counter resets the allowance, which would make the allowance meaningless. Deleting the consent record would leave us unable to show consent was ever given. After you delete your account neither is linked to your phone number or email any more — the binding is gone, and what remains is a counter attached to a random ID.
What we don't collect
None of the following is collected, and the interface never asks for it:
- Name, national ID number, passport number
- Gender, date of birth, age
- Home or company address, precise location
- Payment details (the service is currently free; there is no payment step)
- Contacts, photos, SMS messages, call logs
- Biometrics such as face or fingerprint data
We do no profiling, no targeted advertising, and we do not sell or share your information with any third party for their own purposes.
The cargo dimensions, weights and quantities you enter are not stored on the server either. Once a calculation finishes, all that remains is a count — one run, this many items. Plans and templates you save in the app live in your own browser and are not uploaded.
If we ever do need to collect something new (for example payment details when paid features launch), we will update this policy and ask for your consent again rather than quietly start collecting.
About the device fingerprint, in detail
The fingerprint is the item most likely to make you uneasy, so here it is in full.
It has exactly one purpose: identifying devices to prevent abuse of the free allowance. The allowance is 7 runs for life. If it were tracked by browser storage alone, one click of "clear data" would refill it forever, and "7 free runs" would simply be untrue.
What is collected: canvas and WebGL rendering output, screen resolution and colour depth, time zone, language, CPU core count and memory tier, and whether a dozen or so common fonts are present. All of these are environment traits the browser exposes to web pages on its own. We do not read your files, clipboard, browsing history or any content.
The raw traits never leave your browser. They are hashed locally with sha256 and only the first 32 hex characters of that hash reach us. Those 32 characters cannot be turned back into your GPU model or your font list.
It is also imprecise: two identical machines with identical software can produce the same fingerprint, and switching browsers or updating a graphics driver produces a different one. So we treat it as a layer of friction that raises the cost of abuse — never as authentication — and we do not use it to link your behaviour across sites. We only have this one site.
The local cache is recomputed after 30 days. You can clear your browser's local storage at any time; that removes the cache, but the run counts already recorded on the server do not reset.
Your data is stored in Hong Kong, China (cross-border transfer)
This is the section to pay attention to, and the reason sign-in asks for a separate tick — under Chinese law, consent to a cross-border transfer cannot be bundled into a single "I agree to all of the above".
Why Hong Kong
There is one deployment. The server sits in the Hong Kong Special Administrative Region of China, and users inside and outside mainland China connect to the same machine. Latency from both sides is acceptable there, and a single deployment lets us spend our limited time on the product rather than on operations.
What this means for you: your personal information leaves mainland China and is stored on a server in Hong Kong. Under the Personal Information Protection Law, that is a provision of personal information outside the borders — for the purposes of that law, the Hong Kong SAR counts as outside.
Who the overseas recipient is
- Recipient
- 罗智予(个人) — the operator of this service in person (Individual developer, not a company), personally renting and administering the server
- Location
- Hong Kong Special Administrative Region, China
- Contact
- Phone 17725094982 · Email l2539527429@gmail.com
- Purpose of processing
- Providing registration and sign-in, free-allowance accounting, and running the load calculation service
- Method of processing
- Stored in a database on the server and read/written by the service process; only the operator has access to the server
- Categories of information
- Phone number or email address, hashed session credential, device fingerprint hash, IP address, usage records, consent records
- Retention
- As set out in the table above
- Infrastructure provider
- 腾讯云 Tencent Cloud(中国香港地域) (server and bandwidth in the Hong Kong facility)
One more possible overseas destination, stated up front: the email one-time-code channel is currently configured as Resend(Resend, Inc.,美国), a company based in the United States. That means once email sign-in is switched on, your email address would reach two overseas destinations — Hong Kong and the United States. As of the effective date of this version that channel is not switched on: no message has ever been sent through it and no email address has ever reached the United States. Before switching it on we will update this policy and ask for your consent to that destination separately.
What you can do about it
- Don't tick the box if you don't agree. Without it you can't register — but you can still use the 7 free calculations without signing in.
- Even without signing in, your IP address, browser device fingerprint and cookie identifier still reach that server in Hong Kong, because that is where the free allowance is counted. So the first time you open
/app/you are shown a cross-border notice: until you choose "Agree and continue", the page sends no request to the server at all; choose "Do not agree" and it sends none either and the service is not provided. Your choice is stored in your own browser, and you will be asked again whenever the policy version changes. - If you are not willing to have personal information stored in Hong Kong at all, please don't use the service. That's the only honest answer we can give.
- You can withdraw consent at any time by deleting your account in the app. After withdrawal we stop processing your account information; processing that already happened before withdrawal is not affected.
- You can ask us for a copy of your personal information, or ask us to delete it. See section 08.
Who else touches your information
We do not sell your personal information to anyone. But three kinds of provider are unavoidable in running the service. They process this information only within the scope we entrust to them, and may not use it for their own purposes:
- SMS code provider
阿里云计算有限公司「号码认证服务 · 短信认证」 - Sends and verifies sign-in codes for mainland China mobile numbers. They receive your phone number. The code is generated and checked by them; we never hold it.
- Email delivery provider
Resend(Resend, Inc.,美国) - Delivers the sign-in code to your mailbox. They receive your email address and the contents of that message.
- Server and network provider
腾讯云 Tencent Cloud(中国香港地域), Hong Kong, China - Provides the server, storage and bandwidth. The data physically lives in their facility.
Beyond these, we disclose your information only where the law requires it (for example a lawful request from a judicial authority), and we will tell you where we are permitted to.
Your rights, and how to exercise them
In relation to the personal information we hold about you, you may:
- Access and copy — ask for a copy of what we hold about you;
- Correct and complete — have us fix anything inaccurate;
- Delete — delete your account, or ask us to delete a specific item;
- Withdraw consent — including the separate consent you gave to storage in Hong Kong;
- Ask for an explanation of the processing rules described here;
- Port — where the statutory conditions are met, have your information transferred to another handler you designate.
How
- Delete your account: in the app, open the account menu at the top right → "Delete account". It asks for one more verification code, because the action is irreversible and an unattended keyboard shouldn't be able to destroy your account.
- Anything else: email l2539527429@gmail.com and we will respond within 15 working days. So that we don't hand your information to someone impersonating you, we may ask you to send that email from the phone number or address bound to the account.
What happens when you delete your account
- Your phone number / email is deleted from the database immediately and unbound, so it can be registered again (otherwise the right to deletion would be fiction);
- every session is invalidated at once, on other devices too;
- the account is marked deleted and can no longer sign in;
- for evidentiary purposes we keep a record that "some ID agreed to some version of the terms at some time", plus historical run counts. Neither is linked to any phone number or email any more — the binding is deleted, and what is left is a random ID.
If you believe our handling of your personal information breaks the law, please contact us first. You may also complain to the competent authority or bring a claim.
Minors
The service is aimed at logistics, freight forwarding and export professionals, not at children. We do not knowingly collect personal information from children under 14.
If you are a guardian and find that a child has registered without your consent, contact us and we will delete the information.
How we protect this information
- Everything is transported over HTTPS.
- Session credentials are stored only as hashes — someone who walks off with the database still cannot sign in as you.
- Email codes are stored only as salted hashes, expire in 5 minutes, allow at most 5 attempts, and are rate-limited on sending.
- SMS codes are generated and verified by the SMS provider and are never stored by us.
- Only the first 32 characters of the fingerprint hash are stored; raw traits never leave your browser.
- The most effective measure is simply not collecting what we don't need. What we don't hold can't leak — we have no name, no ID number and no address for you.
No system is perfectly secure. If personal information is leaked, altered or lost, we will take remedial action immediately and notify you and the competent authority as the law requires.
Updates to this policy
We may update this policy. When we do, the version number and effective date at the top of this page change with it.
Every consent you give is recorded against a specific version. So if we change the purposes, the categories of information, the recipients or the cross-border arrangement, your old consent will not be treated as consent to the new version — we will ask again the next time you sign in, including asking again for the separate cross-border consent.
The Chinese version of this policy governs. This English version is provided for convenience; where the two differ in meaning, the Chinese version prevails.
Contact us
Any question, request or complaint about personal information goes here:
- Personal information handler
- 罗智予(个人)
- Contact email
- l2539527429@gmail.com
For matters about the service itself — free allowance rules, disclaimers, disputes — see the Terms of Service.